Service · Direct

Hacked WordPress site repair

A compromised site is usually found by somebody else first. A browser warning, a suspended hosting account, or pages under your domain selling something you do not sell. We work out how it happened, clean it, and deal with the warnings.

Get it assessedBook a call

Hacked sites are looked at the same day, weekends included.

01Signs

How do you know a WordPress site has been hacked?

Most compromises are quiet. A site that stops working gets fixed, and whoever is using yours would rather you did not look. The signs worth acting on:

  • Google shows a warning beside your listing, or the browser blocks the page before it loads.
  • Pages you never wrote are indexed under your domain, usually selling pharmaceuticals, replica goods or gambling.
  • The site is fine when you open it and redirects somewhere else for anyone arriving from a search result, or on a phone.
  • Your host has suspended the account, or sent a notice about spam leaving the server.
  • There are administrator accounts nobody created, or your own login has stopped working.
  • Files have changed and the changes come back after you undo them.

Any one of these is enough to act on. Several together usually means the site has been compromised for longer than anyone thinks.

02Assessment

What does the assessment cover?

Every job starts with a written assessment — what is wrong, what is recoverable, what it will take. It is a smaller commitment than the clean-up, and the clean-up is quoted from it. Nobody prices this sort of work over the phone.

  • How they got in. A vulnerable plugin or theme, a WordPress core version that stopped being updated, a password used in more than one place, or an account on the hosting rather than on the site.
  • What was changed. Files added, core and theme files modified, entries written into the database, scheduled tasks, and user accounts.
  • Whether the server is sending anything out, such as spam or traffic pointed somewhere that is not yours.
  • What backups exist, how old they are, and whether they predate the compromise. A backup taken afterwards restores the compromise with everything else.
  • Whether Google, Safe Browsing or your host has flagged the site, and what each of them wants before it is lifted.

A hacked site is looked at the same day, including at weekends. That is how we treat compromises specifically. It is not a service level term and it is not the published response commitment, which applies to sites on a support agreement.

03Clean-up

What does cleaning up a hacked WordPress site involve?

Take it out of service

The live site is either shut down or put behind a holding page, and which of the two depends on the site and on what you need it to do while the work runs. Leaving a compromised site serving traffic extends both the damage and the warning that comes with it. Passwords and keys are rotated at the same time.

Work on a copy, not on your server

The site is pulled down onto a quarantined server and the clean-up happens there, then on staging. Nothing is repaired underneath live traffic, which means there is a working copy to compare against, no half-cleaned state is ever public, and the site that goes back up is one that has been checked in full rather than fixed in stages.

Replace, do not repair

WordPress core, plugins and themes are replaced with clean copies from source instead of being edited back into shape, because an overwritten file is easier to trust than a corrected one. Custom code is the exception and it gets read. Where a component has no clean source to replace it from, because it was nulled, abandoned or modified in place, it goes in the assessment with a recommendation to fix it or drop it, and that is your decision to make.

Find what is left behind

Injected content in the database, spam pages, hidden links, rogue scheduled tasks, rewritten server rules, and files dropped outside the WordPress install. A clean-up that only covers the WordPress directory is the usual reason a site comes back infected.

Close the way in

The vulnerability that was used is fixed, or the component is removed. Where the assessment cannot establish how they got in, we say so plainly instead of implying the question is settled.

Sort out the accounts

Administrator accounts nobody recognises are the ones worth looking at hardest, and they are also the ones easiest to get wrong. An unfamiliar account is often a previous agency, a developer who has moved on, or a service account a plugin created. We list them, tell you what each one looks like, and agree which are going before any of them is deleted.

Check it, then put it back

The cleaned site is gone over again against what the assessment found, and only then deployed from staging to replace the compromised one. The review requests to Google and to your host come after that, not before.

04Warnings

Getting the warnings and suspensions lifted

Cleaning the site is half of it. The other half is satisfying everyone who flagged it, and each of them has its own process.

We handle the Search Console review request for a site flagged as hacked, the Safe Browsing warning that browsers show in front of the page, and the host that has suspended the account. All three want evidence rather than assurance: what was found, what was removed, and what has changed so that it does not recur. The assessment and the record of the clean-up are what supply it.

The timings belong to Google and to your host, so we do not put a number on them. What we will say is that a review requested before the site is genuinely clean is the common way this goes wrong, because a failed review costs more time than waiting would have.

05Reinfection

Why do cleaned WordPress sites get hacked again?

Reinfection is common, and it is almost always one of a short list:

A backdoor survived the clean.They are written to be missed. One file with a plausible name, an extra line in a theme function, a database entry that rewrites a page as it is served.

The restore point was already compromised.Rolling back to last month’s backup puts last month’s backdoor back with it.

The way in was never closed.The same out-of-date plugin is still installed, or the credentials that were used are still valid somewhere.

Credentials were reused.A password that also opens the hosting account, the email or the database means the site was only one of the doors standing open.

Nothing changed afterwards.An install that was not being updated before the compromise is generally not being updated after it either.

The clean-up deals with the first four. The fifth is not a one-off fix. What prevents it is ordinary maintenance: updates applied and checked, backups held off the server and tested, access reviewed. You can run that yourself, or it is what website support and maintenance covers.

06Afterwards

What happens once the site is clean?

The clean-up is a one-off piece of work, not a monthly charge. It finishes when the site is stable and the warnings are gone.

From there the site can move onto a support agreement, where the updates, backups, monitoring and access review are somebody’s job between now and the next time something needs attention. That is a separate decision and it is not bundled into the repair.

If the install was already difficult to maintain before it was compromised, rebuilding it is sometimes the better use of the money. We will say so before anyone pays to clean the same site twice. See WordPress development for that, or managed hosting if the server needs to move as well.

07FAQ

Questions we get asked

What do you need to scope the work?

To scope a hacked WordPress repair we need the site’s address, access to the hosting, access to the WordPress admin where that still works, and anything you have already been told about the problem, such as a host suspension notice or a message in Search Console. From that we produce a written assessment: what is wrong, what is recoverable, and what it will take. The assessment covers how they got in, what was changed in the files and in the database, whether the server is sending anything out, what backups exist and whether they predate the compromise, and whether Google, Safe Browsing or your host has flagged the site. The clean-up is quoted from that assessment, and you see the price before any of it starts. A hacked site is looked at the same day, including at weekends, which is specific to compromised sites and is not a service level commitment. If you have lost access to the site itself, say so, because the hosting account is usually enough to work from.

How long does it take to clean a hacked WordPress site?

It depends on what the assessment finds, and we do not quote a turnaround before we have looked. A site running a stock set of plugins with a recent clean backup is a different job from an install with years of custom code, no working backup, and more than one compromise layered on top of the last. A hacked site is looked at the same day, including at weekends, so you will know what you are dealing with early even if the work itself takes longer. The part nobody can put a time on is what happens after the site is clean. Google processes the Search Console review request on its own schedule, the Safe Browsing warning clears on theirs, and a suspended hosting account is released when the host is satisfied. Those timings are set by them and not by us, which is why there is no number on this page. Asking for a review before the site is genuinely clean makes it longer, not shorter.

Can we just restore a backup?

Sometimes, and it is worth establishing first, which is why backups are part of the assessment. A restore only helps when the backup predates the compromise, and a compromise is often weeks or months old by the time anyone notices, so the obvious restore point frequently contains the problem already. A restore also puts back the vulnerability that was used in the first place, so an out-of-date plugin or a reused password is live again the moment the site is up. And it loses whatever legitimate content, orders and form submissions arrived in the meantime. Where a genuinely clean backup does exist, restoring it and then closing the way in is quicker and cheaper than a full clean-up, and we will tell you that rather than quote for the larger job. Where it does not, the site is cleaned properly instead: taken out of service, copied onto a quarantined server, and worked on there rather than underneath live traffic. Core, plugins and themes are replaced from source, the database is checked for injected content, the files outside the WordPress install are checked too, and the result is deployed from staging once it has been gone over again.

Will this get the Google warning removed?

Cleaning the site is what makes the warning removable, and the removal itself is a review you have to ask for. We submit the Search Console review request for a site flagged as hacked, deal with the Safe Browsing warning that browsers show in front of the page, and handle the host where the account has been suspended. None of them will take your word for it. They want the detail of what was on the site, how it was removed, and why it will not come back, which is what the written assessment and the record of the clean-up are for. A site that is not verified in Search Console has to be verified before a review can be requested at all. Review times are set by Google and by your host, so we do not put a number on them. If the site was compromised for a while, expect the spam pages under your domain to sit in search results for a period after the warning clears, until they are recrawled and dropped.

What stops it happening again?

Reinfection almost always has one of a short list of causes: a backdoor that survived the clean, a restore point that was already compromised, a way in that was never closed, credentials reused somewhere else, or an install that went straight back to not being updated. The clean-up addresses the first four directly. The site comes down onto a quarantined server so none of the work happens underneath live traffic, core, plugins and themes are replaced with clean copies from source instead of being edited, the database and the files outside the WordPress install are both checked, and keys and passwords are rotated. Administrator accounts nobody recognises are listed and agreed with you before any of them is deleted, because an unfamiliar account is often a previous agency or something a plugin created. Where the assessment cannot establish how they got in, we say so instead of implying the question is settled. The fifth cause is the one the repair cannot settle on its own, because an install that was not being looked after before will not look after itself afterwards. Somebody has to keep applying the updates, testing the backups and reviewing who still has access. You can do that yourself, or the site can move onto a support agreement once it is stable, which is a separate decision from the repair.

Can you work on a site you did not build, or one we have lost access to?

Yes. What we need is access, and hosting access is usually enough on its own, because the files, the database and the server logs are all reachable from there even when the WordPress admin is locked, broken, or serving something that is not yours. If the host has suspended the account, the hosting is the only way in anyway, and getting the suspension lifted is part of the work. Where you hold the domain but no longer know who holds the hosting, say so at the start, because tracing it takes time and it changes the order the work happens in. Nothing is changed on the site before you have agreed the written assessment, other than steps to stop an active compromise doing further damage, and we would agree those with you first. The assessment tells you what is recoverable as well as what is wrong, which matters most on a site nobody has the original code for.

08Next step

Get it assessed

Send the site’s address and anything you have already been told about the problem. The written assessment comes first, before anything is quoted.

Or email us at [email protected].

Agency cleaning up a client’s site? White-label website support